How you respond in that first week tells the client more about your professionalism than any welcome packet you sent them.
This guide is for the VA who is about to be handed access to a client's accounts and wants to do it right, not just quickly.
Why the Access Conversation Matters More Than You Think
Most clients have never thought carefully about how they share account access. They default to whatever feels fastest, which usually means a password copied into a DM, an email with login credentials in plain text, or a spreadsheet shared via Google Drive with permissions left wide open.
When you push back on that and offer a better way, you do not look difficult. You look like someone who has been here before. That is a significant credibility signal before you have completed a single task.
The Rule That Is Not Negotiable: Never Accept a Password Over DM or Email
Passwords sent through messaging apps or email are exposed at every point along the way. If either party's account is ever compromised, those credentials are sitting right there in a conversation thread or inbox. This is not a hypothetical risk. It is the most common way business accounts get taken over.
If a client tries to share a login this way, the response is simple: "Let's use a more secure method. Here is what I'd suggest." Then give them one of the options below.
This also matters for your own liability. If something goes wrong with a client account and you were handling the login over DM, that context will be part of any dispute.
Use Delegated Access Wherever the Platform Allows It
The cleanest solution is also the most professional one. Most major platforms have a way to give a second user access without sharing the account password at all. Here is what that looks like on the platforms you will encounter most often.
- Meta Business Suite. Your client adds you as a partner or team member through Business Manager with a defined role. You access the account through your own Facebook login. The client's personal password never changes hands.
- Google Workspace. A client can set you up as a delegated user on Gmail, give you editor access to Drive folders, or add you to Google Analytics as a viewer or editor. You log in with credentials tied to that workspace, not the client's personal account.
- LinkedIn, Pinterest, Tailwind, Buffer, Hootsuite, and most scheduling tools. All have seat-based or team access. Ask the client to add your email address with the appropriate permission level rather than handing you their login.
- Shopify, WordPress, Squarespace. All support additional user accounts with role-based access. A client can create a separate VA login, which means their own admin credentials are never shared and can be revoked cleanly when the contract ends.
If the platform supports it, delegated access is always the right answer.
Related: Client onboarding for VAs, step by step
When a Shared Login Genuinely Cannot Be Avoided
Some platforms do not support multiple users. Some clients are on legacy tools that predate the concept. In those cases, a password manager is the only acceptable method for handling shared credentials.
Tools like 1Password, Bitwarden, and LastPass all have a shared vault or item-sharing feature. The client creates an entry for the login, shares it with your account via the password manager, and you access it from there. The password itself is never visible in a chat thread or email.
This approach also means that when the client updates the password, the vault updates automatically. You are always working with current credentials and neither of you has to chase the other down.
Encourage clients who are not already using a password manager to set one up before onboarding starts. This is something the Virtueasy onboarding kit covers in the setup checklist.
Related: The VA client onboarding system that makes you look like a pro from day one
Handling Two-Factor Authentication Without Becoming the Bottleneck
Two-factor authentication (2FA) is a layer of security worth keeping in place, but if the 2FA code is sent to the client's phone and you need it to log in, you are now blocked every time you need access.
There are a few ways to handle this without removing the protection entirely. The first is to ask whether the platform supports an authenticator app. Google Authenticator and Authy both allow a QR code to be shared, which means the client can set up the app on their device and you can set it up on yours using the same underlying code. Both generate valid login codes independently.
The second option, available on some platforms, is to add a secondary trusted phone number or email address. This can be a dedicated VA number or email that routes codes to you without removing the client's primary 2FA setup.
What you should never do is ask a client to turn off 2FA just to make your access easier. That conversation should not happen.
What to Put in Your Client Agreement
Secure password management for virtual assistants is not just about tools. It also requires clarity on paper. Your client agreement or a standalone data handling addendum should cover the following.
- How credentials will be shared: delegated access where possible, password manager vault otherwise, never over DM or email.
- Who is responsible for revoking access at the end of the contract.
- What happens if a breach is suspected, including who notifies whom and within what timeframe.
- Confirmation that credentials will not be stored beyond the contract period.
- A note that you will not share access with any third party without written permission.
This does not need to be a lengthy legal document. A clear, plain-language section in your standard contract covers the essentials and signals that you take client data protection seriously.
Related: What to put in your VA contract before you start work
What to Do If You Suspect a Breach
If you notice unusual account activity, a login from an unrecognized location, or anything that suggests credentials may have been compromised, contact the client the same day. Do not wait to see if it resolves. The steps are: flag it immediately, change the affected credentials via the password manager or delegated access settings, review recent account activity, and document what you noticed and when.
Your legal and ethical responsibility as a VA is to handle client information with the same care you would want applied to your own. Most data protection obligations do not disappear because you are a contractor rather than an employee.
Handing Access Back Cleanly When the Contract Ends
Offboarding access is just as important as setting it up. At the end of every contract, go through every platform you had access to and confirm with the client that your access has been revoked. If you were using shared vault entries in a password manager, confirm those have been removed or that the passwords have been changed. If the client added you as a team member anywhere, verify that your seat has been deactivated.
Keep a running list of every platform you were given access to. This is for your protection as much as the client's.
A clean offboarding is what makes a client comfortable referring you. It closes the loop.
The VA who handles access well at the start of a contract is the one who gets asked back. Get this right in week one and it will not come up again.